Files
2025-11-21 23:31:35 +01:00

159 lines
3.9 KiB
YAML
Executable File

#!/usr/bin/ansible-playbook --inventory=localhost,
---
- hosts: localhost
connection: local
force_handlers: true
vars:
ansible_python_interpreter: auto_silent
vars_files:
- secret_vars.yml
# check if user == root
pre_tasks:
- set_fact:
eff_uid_number: "{{ lookup('pipe', 'id -u') }}"
- block:
- debug:
msg: "Run as root!"
- meta: end_play
when: eff_uid_number|int != 0
# run playbook
tasks:
- name: include distibution vars
ansible.builtin.include_vars:
file: "vars_{{ ansible_distribution | lower }}.yml"
# prepare ansible user
- name: create ansible user
user:
name: "{{ admin_user_ansible }}"
uid: 2001
groups: "{{ sudo_group }}"
shell: /bin/bash
home: /srv/ansible
comment: Ansible Service User
- name: set ansible user sudo passless
copy:
dest: "/etc/sudoers.d/adm-ansible"
content: "adm-ansible ALL=(ALL) NOPASSWD: ALL"
mode: 0600
owner: root
- name: add ansible auth key
no_log: true
ansible.posix.authorized_key:
user: adm-ansible
key: "{{ ssh_key_ansible }}"
- name: enable ssh
systemd:
name: sshd
state: started
enabled: yes
- name: set ssh port
lineinfile:
dest: /etc/ssh/sshd_config
regex: "^[#]?Port"
line: "Port {{ ssh_port }}"
notify: restart sshd
- name: disable ansible password login
blockinfile:
dest: /etc/ssh/sshd_config
block: |
Match User {{ admin_user_ansible }}
PasswordAuthentication no
notify: restart sshd
# installs
- name: install default packages with package manager
ansible.builtin.package:
name:
- "{{ item }}"
state: present
loop: "{{ package_installs }}"
when: package_installs is defined
# debian tasks
- name: import distribution tasks
ignore_errors: yes
ansible.builtin.include_tasks:
file: "tasks_{{ ansible_distribution }}.yml"
- name: ensure dirs exist
ansible.builtin.file:
path: "{{ item.value }}"
state: directory
mode: '0777'
loop: "{{ directorys | dict2items}}"
when: directorys is defined
- name: get appimage programms
ansible.builtin.get_url:
url: "{{ item.url }}"
dest: "{{ directorys.appimage_dir }}/{{ item.name }}.appimage"
mode: '0775'
loop: "{{ appimages }}"
when: appimages is defined
- name: get executable programms
ansible.builtin.get_url:
url: "{{ item.url }}"
dest: "/usr/bin/{{ item.name }}"
mode: '0775'
loop: "{{ executables }}"
when: executables is defined
# wireguard setup
- name: check file wg0
no_log: true
stat:
path: /etc/wireguard/wg0.conf
register: interface_wg0
- name: create client wireguard config
no_log: true
template:
dest: /etc/wireguard/wg1.conf
src: client_wg1.conf.j2
owner: root
group: root
mode: '0600'
when: not interface_wg0.stat.exists
notify: restart wg-quick@wg1
- name: start wireguard and enable on boot
no_log: true
systemd:
name: wg-quick@wg1
enabled: yes
state: started
when: not interface_wg0.stat.exists
notify: discord push
handlers:
- name: restart sshd
systemd:
name: sshd
state: restarted
- name: restart wg-quick@wg1
systemd:
name: sshd
state: restarted
- name: discord push
no_log: true
uri:
url: "{{ discord_url }}"
method: 'POST'
body_format: json
body: {
'content': "i am online",
'username': "{{ ansible_hostname }}"
}
status_code: 204